北京邮电大学学报

  • EI核心期刊

北京邮电大学学报 ›› 2005, Vol. 28 ›› Issue (4): 103-106.doi: 10.13190/jbupt.200504.103.xianjq

• 研究报告 • 上一篇    下一篇

基于CSA无监督模糊聚类算法的异常检测方法

鲜继清1,郎风华2   

  1. 1重庆邮电学院 自动化学院, 重庆 400065; 2重庆邮电学院 计算机学院, 重庆 400065
  • 出版日期:2005-08-28 发布日期:2005-08-28

Anomaly Detection Method Based on CSABased Unsupervised Fuzzy Clustering Algorithm

XIAN Jiqing1,LANG Fenghua2   

  1. 1School of Automation, Chongqing University of Posts and Telecommunications, Chongqing 400065, China; 2School of Computer, Chongqing University of Posts and Telecommunications, Cho ngqing 400065, Chin
  • Online:2005-08-28 Published:2005-08-28

摘要:

为解决模糊k均值算法对初始化敏感及易陷入局部极值的不足,提出了基于克隆选择算法(CSA)的无监督模糊聚类异常入侵检测方法. 应用结合了具有进化搜索、全局搜索、随 机搜索和局部搜索特点的克隆算子快速得到了全局最优聚类,并应用模糊检测算法检测网络中的异常行为模式. 该方法的优点是不需要人工对训练集分类,并且可以检测出未知的攻击. 仿真试验表明,该方法不但能检测出未知的攻击,而且具有较低的误报率和较高的检测率.

关键词: 异常检测, 模糊聚类, 克隆选择算法, 无监督模糊k均值算法

Abstract:

A novel intrusion detection method based on clonal selection algorithm (CSA)based unsupervised fuzzy clustering algorithm was presented for solving the problem of fuzzy kmeans algorithm which is much more sensitive to the initialization and is easy to fall intolocal optimization. With the method, the global optimal clustering with clonal operator which combines the evolutionary search, the global search, the stochastic search and the local search could be quickly obtained, in the mean time, the abnormal network behavior patterns with fuzzy detection algorithm could be detected. The benefit of this algorithm is that it does not need the labeled trainingdata sets and it could detect unknown intrusion. Simulation results show that the method mentioned above will be able to detect unknown intrusions with lower false positive rate and higher detection rate.

Key words: anomaly detection, fuzzy clustering, clonal selection algorithm, unsupervised fuzzy kmeans algorithm

中图分类号: